Executive brief
A security vulnerability has been identified in qihang-wms, a warehouse management system used for e-commerce operations. The flaw exists in the order import component, which fails to properly validate uploaded files. An attacker could exploit this to upload malicious scripts to the server, potentially leading to a full system takeover, data theft, or service disruption.
Technical details
An arbitrary file upload and directory traversal vulnerability exists in the ShopOrderImportController.java component of qihang-wms (specifically commit 75c15a). The root cause is the improper handling of file extensions, which are obtained and directly concatenated to the storage path without sufficient sanitization. This allows a remote attacker to use directory traversal sequences (e.g., ../) to save files in unintended locations or upload executable scripts (such as web shells) to the server. Successful exploitation can lead to unauthorized remote code execution (RCE), sensitive file overwrites, or stored cross-site scripting (XSS).
Affected products
- qihangerp.cn qihang-wms (启航电商WMS) V4.0 (commit 75c15a)
Timeline
- 2026-05-13: disclosed: Vulnerability details published via GitHub and NVD.
- 2026-05-13: advisory